← Trust

Data Processing Addendum

Version 1.0, 4 September 2026

This Addendum forms part of the agreement between Creativefuel Private Limited, Indore, Madhya Pradesh, India ("Processor", "we") and the customer organization that has subscribed to Speech ("Controller", "you"). Where this Addendum and the Terms of Service conflict on the processing of personal data, this Addendum governs.

To have this signed, write to support@creativefuel.io with your organization's legal name and address. We will return an executed copy. If your procurement requires your own paper instead, send it and we will review it.

1. Roles

You are the Controller of the personal data your people put into Speech. We are the Processor, and we process it only on your documented instructions, which are this Addendum, the agreement, and your use of the product's own settings. If we ever believe an instruction breaks applicable law, we will tell you rather than act on it.

2. What is processed

Categories of data subjectYour employees, contractors and other people you give accounts to.
Categories of personal dataEmail address; display name; audio a person dictates; the text transcribed from it; a short snippet of text immediately before the cursor; usage and diagnostic records; text a person selects when using Agent Mode; images generated at a person's request; bug reports a person sends, with any screenshot they attach.
Special categoriesNone are requested. Dictation is free-form speech, so a person may say anything; we do not scan for, index or infer special-category data, and Privacy Mode exists so that content need never be retained at all.
Nature and purposeTranscribing speech to text, formatting it, returning it to the person's device, and operating and improving the service.
DurationFor the term of the agreement, and then as set out in section 8.

3. Confidentiality

Access to your data is limited to the people who need it to run the service, each bound by confidentiality obligations that survive their engagement. Access to dictation CONTENT is further restricted: it is unreadable to us unless the individual has switched sharing on for their own account, and every content read is recorded in an append-only audit log.

4. Security measures

We maintain at least the following, which are described in plain language on the trust page:

We may change these measures, but not in a way that materially reduces the level of protection.

5. Subprocessors

You authorise the subprocessors listed at speech.rupees.com/subprocessors.html, which forms Annex 2 of this Addendum and is the authoritative list. Each is bound by written terms no less protective than these, and we remain responsible for their performance.

We will give you at least 30 days notice before a new subprocessor begins processing your content. If you reasonably object on data protection grounds within that period and we cannot offer an alternative, you may terminate the affected subscription and receive a pro-rata refund of prepaid fees.

6. International transfers

Your data is stored and processed in India (AWS ap-south-1, Mumbai). Two model providers used to transcribe or format a dictation operate in the United States, so content transits there for the seconds it takes to process and is not stored there.

Where you are established in the EEA, the United Kingdom or Switzerland and a transfer requires a lawful mechanism, the European Commission's Standard Contractual Clauses (Decision 2021/914, Module Two, controller to processor) are incorporated into this Addendum by reference, together with the UK International Data Transfer Addendum where the UK GDPR applies. This Addendum's Annexes serve as the Clauses' Annexes: section 2 as Annex I.B, section 4 as Annex II, and section 5 as Annex III. The governing law and forum are those of the agreement to the extent the Clauses permit.

7. Assistance to you

8. Return and deletion

You may export your data at any time while the agreement is in force. On termination, and on your written request within 30 days of it, we will delete your organization's personal data. Absent a request, we delete it within 90 days of termination. Backups age out on their own 60 day cycle and are not restored except to recover the service.

9. Audit

We will answer reasonable security questionnaires and provide our then-current security documentation once a year, and more often after a security incident affecting your data. Where that is not sufficient for your regulator, we will agree a proportionate on-site or remote audit with reasonable notice, during business hours, under confidentiality, and at your cost.

We hold no SOC 2 report and no ISO/IEC 27001 certificate today. We say so here rather than let a questionnaire discover it.

10. Indian law

Where the Digital Personal Data Protection Act, 2023 applies, we act as a Data Processor to you as Data Fiduciary, process personal data only on your instructions, assist you with the obligations that Act places on you, and maintain the security safeguards in section 4. Our Grievance Officer's contact details are in the privacy policy, section 10.

11. Liability and term

Each party's liability under this Addendum is subject to the limitations and exclusions in the agreement. This Addendum takes effect when the agreement does and continues until we have deleted your organization's personal data under section 8.

Trust page · Subprocessors · Privacy policy · Terms

Speech by Creativefuel